ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1685
Disable or Modify Tools
MalwareNanoCore

NanoCore can modify the victim's anti-virus.

T1685
Disable or Modify Tools
MalwareGold Dragon

Gold Dragon terminates anti-malware processes if they’re found running on the system.

T1685
Disable or Modify Tools
MalwareCarberp

Carberp has attempted to disable security software by creating a suspended process for the security software and injecting code to delete antivirus core files when the process is resumed.

T1685
Disable or Modify Tools
MalwareTinyZBot

TinyZBot can disable Avira anti-virus.

T1685
Disable or Modify Tools
MalwareProton

Proton kills security tools like Wireshark that are running.

T1685
Disable or Modify Tools
MalwareMango

Mango contains an unused capability to block endpoint security solutions from loading user-mode code hooks via a DLL in a specified process by using the `UpdateProcThreadAttribute API` to set the `PROC_THREAD_ATTRIBUTE_MITIGATION_POLICY` to `PROCESS_CREATION_MITIGATION_POLICY_BLOCK_NON_MICROSOFT_BINARIES_ALWAYS_ON` for an identified process.

T1685
Disable or Modify Tools
MalwarePHASEJAM

PHASEJAM has modified Ivanti Connect Secure appliances and blocks the system upgrades by altering the DSUpgrade.pm file.

T1685
Disable or Modify Tools
MalwareClop

Clop can uninstall or disable security products.

T1685
Disable or Modify Tools
MalwareEgregor

Egregor has disabled Windows Defender to evade protections.

T1685
Disable or Modify Tools
MalwareStealBit

StealBit can configure processes to not display certain Windows error messages by through use of the `NtSetInformationProcess`.

T1685
Disable or Modify Tools
MalwareZxShell

ZxShell can kill AV products' processes.

T1685
Disable or Modify Tools
MalwareSPAWNCHIMERA

SPAWNCHIMERA has modified the Ivanti Integrity Checker Tool to evade detection.

T1685
Disable or Modify Tools
MalwareEbury

Ebury can disable SELinux Role-Based Access Control and deactivate PAM modules.

T1685
Disable or Modify Tools
MalwareMeteor

Meteor can attempt to uninstall Kaspersky Antivirus or remove the Kaspersky license; it can also add all files and folders related to the attack to the Windows Defender exclusion list.

T1685
Disable or Modify Tools
MalwareZIPLINE

ZIPLINE can add itself to the exclusion list for the Ivanti Connect Secure Integrity Checker Tool if the `--exclude` parameter is passed by the `tar` process.

T1685
Disable or Modify Tools
MalwareMaze

Maze has disabled dynamic analysis and other security tools including IDA debugger, x32dbg, and OllyDbg. It has also disabled Windows Defender's Real-Time Monitoring feature and attempted to disable endpoint protection services.

T1685
Disable or Modify Tools
MalwareChChes

ChChes can alter the victim's proxy configuration.

T1685
Disable or Modify Tools
MalwareShai-Hulud

Shai-Hulud has replaced DNS configuration from `/tmp/resolved.conf` in order to gain control of network-level control within CI environments and has flushed iptables rules using `sudo iptables -F OUTPUT` and `sudo iptables -F DOCKER-USER`.

T1685
Disable or Modify Tools
MalwareJPIN

JPIN can lower security settings by changing Registry keys.

T1685
Disable or Modify Tools
MalwareKOCTOPUS

KOCTOPUS will attempt to delete or disable all Registry keys and scheduled tasks related to Microsoft Security Defender and Security Essentials.

T1685
Disable or Modify Tools
MalwareQilin

Qilin can terminate antivirus-related processes and services.

T1685
Disable or Modify Tools
MalwareLazyWiper

LazyWiper can disable Microsoft Windows Defender Real-Time Monitoring with the `Set-MpPreference` cmdlet.

T1685
Disable or Modify Tools
MalwareAgent Tesla

Agent Tesla has the capability to kill any running analysis processes and AV software.

T1685
Disable or Modify Tools
MalwarePOWERSTATS

POWERSTATS can disable Microsoft Office Protected View by changing Registry keys.

T1685
Disable or Modify Tools
MalwareDRYHOOK

DRYHOOK has killed all instances of the `cgi-server` process in order for the modified Perl module to be activated.

T1685
Disable or Modify Tools
MalwareGoopy

Goopy has the ability to disable Microsoft Outlook's security policies to disable macro warnings.

T1685
Disable or Modify Tools
MalwareQakBot

QakBot has the ability to modify the Registry to add its binaries to the Windows Defender exclusion list.

T1685
Disable or Modify Tools
MalwareSplatCloak

SplatCloak has identified and disabled API callback features of Windows Defender and Kaspersky.

T1685
Disable or Modify Tools
MalwareWaterbear

Waterbear can hook the ZwOpenProcess and GetExtendedTcpTable APIs called by the process of a security product to hide PIDs and TCP records from detection.

T1685
Disable or Modify Tools
MalwareH1N1

H1N1 kills and disables services for Windows Security Center, and Windows Defender.

T1685
Disable or Modify Tools
MalwareWarzoneRAT

WarzoneRAT can disarm Windows Defender during the UAC process to evade detection.

T1685
Disable or Modify Tools
ToolSILENTTRINITY

SILENTTRINITY's `amsiPatch.py` module can disable Antimalware Scan Interface (AMSI) functions.

T1685
Disable or Modify Tools
ToolDCRAT

DCRAT can patch Microsoft’s Antimalware Scan Interface (AMSI) to evade detection.

T1685
Disable or Modify Tools
ToolBrute Ratel C4

Brute Ratel C4 has the ability to hide memory artifacts and to patch Event Tracing for Windows (ETW) and the Anti Malware Scan Interface (AMSI).

T1685
Disable or Modify Tools
ToolImminent Monitor

Imminent Monitor has a feature to disable Windows Task Manager.

T1685
Disable or Modify Tools
ToolDonut

Donut can patch Antimalware Scan Interface (AMSI), Windows Lockdown Policy (WLDP), as well as exit-related Native API functions to avoid process termination.

T1685.001
Disable or Modify Windows Event Log
ToolWevtutil

Wevtutil can be used to disable specific event logs on the system.

T1685.002
Disable or Modify Cloud Log
ToolPacu

Pacu can disable or otherwise restrict various AWS logging services, such as AWS CloudTrail and VPC flow logs.

T1685.003
Modify or Spoof Tool UI
MalwarePHASEJAM

PHASEJAM has prevented legitimate Ivanti Connect Secure system upgrades by intercepting the upgrade command and rendering fake HTML upgrade progress bar through a function called `processUpgradeDisplay()` which allowed the compromised device to remain under the control of the adversary.

T1685.004
Disable or Modify Linux Audit System Log
MalwareEbury

Ebury disables OpenSSH, system (`systemd`), and audit logs (`/sbin/auditd`) when the backdoor is active.

T1685.005
Clear Windows Event Logs
MalwareSynAck

SynAck clears event logs.

T1685.005
Clear Windows Event Logs
MalwareRansomHub

RansomHub can delete events from the Security, System, and Application logs.

T1685.005
Clear Windows Event Logs
MalwareOlympic Destroyer

Olympic Destroyer will attempt to clear the System and Security event logs using wevtutil.

T1685.005
Clear Windows Event Logs
MalwareDUSTTRAP

DUSTTRAP can delete infected system log information.

T1685.005
Clear Windows Event Logs
MalwareMafalda

Mafalda can delete Windows Event logs by invoking the `OpenEventLogW` and `ClearEventLogW` functions.

T1685.005
Clear Windows Event Logs
MalwareShrinkLocker

ShrinkLocker calls Wevtutil to clear the Windows PowerShell and Microsoft-Windows-Powershell/Operational logs.

T1685.005
Clear Windows Event Logs
MalwareApostle

Apostle will attempt to delete all event logs on a victim machine following file wipe activity.

T1685.005
Clear Windows Event Logs
MalwareBlackCat

BlackCat can clear Windows event logs using `wevtutil.exe`.

T1685.005
Clear Windows Event Logs
MalwareLucifer

Lucifer can clear and remove event logs.

T1685.005
Clear Windows Event Logs
MalwareBlackEnergy

The BlackEnergy component KillDisk is capable of deleting Windows Event Logs.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.